Australia markets closed

    +21.20 (+0.31%)

    -0.0011 (-0.16%)
  • ASX 200

    +16.70 (+0.25%)
  • OIL

    +1.39 (+1.28%)
  • GOLD

    +8.90 (+0.49%)

    +1,554.62 (+5.53%)
  • CMC Crypto 200

    +22.53 (+5.36%)

Apple issues urgent warning to millions about iPhone hacks

·3-min read
Close up of hands holding iPhone. Apple logo in white.
Apple users have been urged to update their devices. (Images: Getty).

Millions of iPhone users around the world have been urged to update their operating systems after researchers uncovered a vulnerability allowing hackers to infiltrate devices without users even clicking a link.

Apple released the urgent update on Monday, with users of iPhone 6 and later, all iPad Pro models, iPad Air 2 and later, iPad 5th generation and later, iPod Touch 7th generation and iPad mini 4 and later reminded to update their devices.

The flaw in the iMessage software allowed hackers to infect devices without the users clicking a malicious link.

Instead, it comes from a weakness in the way iMessage automatically renders images, researchers from the University of Toronto’s information and communications security department Citizen Lab found.

In this case, the hackers silently sent corrupt files that appeared to be .GIF extensions, but were actually Adobe PDF files that held dangerous code. It has already been exploited by clients of Israeli spyware firm NSO Group, the researchers claim.

Citizen Lab was the first to uncover the vulnerability while examining a Saudi activist’s phone, and claims the flaw has been exploited since February 2021.

In a blog post, the Lab said it was highly confident the flaw had allowed hackers to infect devices with the NSO Group’s Pegasus spyware.

Pegasus spyware can hack into a device and harvest information, intercept calls and messages and even record.

In 2019, Facebook accused NSO Group of being complicit in the hacking of 1,400 devices through WhatsApp.

However, NSO Group disputed those allegations and maintains that its spyware is only meant to be used by government and law enforcement agencies to target and monitor criminals and terrorists.

Apple security engineering and architecture head Ivan Krstić thanked Citizen Lab for identifying the vulnerability.

"Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals,” he said in a statement.

He added that while the vulnerability is significant, it’s not considered a threat to most Apple users.

Apple has not issued a comment on whether the hacking technique was developed by NSO Group.

Citizen Lab said its research highlights the risks messaging apps can pose to phones, and the importance of ensuring those apps are secure.

“Ubiquitous chat apps have become a major target for the most sophisticated threat actors, including nation state espionage operations and the mercenary spyware companies that service them,” Citizen Lab said.

“As presently engineered, many chat apps have become an irresistible soft target. Without intense engineering focus, we believe that they will continue to be heavily targeted, and successfully exploited.”

How to update your device

Apple users can update their devices by heading to Settings, then General and then tap Software Update and Install Now.

You can either set your device to automatically update when attached to power, or select to install any updates then and there. Generally speaking, you will need to attach your device to power and be connected to WiFi or mobile data to update your device.

Follow Yahoo Finance on Facebook, LinkedIn, Instagram and Twitter, and subscribe to the free Fully Briefed daily newsletter.

Sign up to get Fully Briefed every business day and Rich Thinking every fortnight, straight to your inbox.
Sign up to get Fully Briefed every business day and Rich Thinking every fortnight, straight to your inbox.
Our goal is to create a safe and engaging place for users to connect over interests and passions. In order to improve our community experience, we are temporarily suspending article commenting